{"id":"https://openalex.org/W3090890096","doi":"https://doi.org/10.1007/978-3-030-59817-4_2","title":"Reducing the Forensic Footprint with Android Accessibility Attacks","display_name":"Reducing the Forensic Footprint with Android Accessibility Attacks","publication_year":2020,"publication_date":"2020-01-01","ids":{"openalex":"https://openalex.org/W3090890096","doi":"https://doi.org/10.1007/978-3-030-59817-4_2","mag":"3090890096"},"language":"en","primary_location":{"id":"doi:10.1007/978-3-030-59817-4_2","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-030-59817-4_2","pdf_url":"https://link.springer.com/content/pdf/10.1007%2F978-3-030-59817-4_2.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://link.springer.com/content/pdf/10.1007%2F978-3-030-59817-4_2.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5076988563","display_name":"Yonas Leguesse","orcid":"https://orcid.org/0000-0002-7997-0063"},"institutions":[{"id":"https://openalex.org/I197854408","display_name":"University of Malta","ror":"https://ror.org/03a62bv60","country_code":"MT","type":"education","lineage":["https://openalex.org/I197854408"]}],"countries":["MT"],"is_corresponding":false,"raw_author_name":"Yonas Leguesse","raw_affiliation_strings":["Department of Computer Science, University of Malta, Msida, Malta"],"raw_orcid":"https://orcid.org/0000-0002-7997-0063","affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Malta, Msida, Malta","institution_ids":["https://openalex.org/I197854408"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5011178945","display_name":"Mark Vella","orcid":"https://orcid.org/0000-0002-6483-9054"},"institutions":[{"id":"https://openalex.org/I197854408","display_name":"University of Malta","ror":"https://ror.org/03a62bv60","country_code":"MT","type":"education","lineage":["https://openalex.org/I197854408"]}],"countries":["MT"],"is_corresponding":false,"raw_author_name":"Mark Vella","raw_affiliation_strings":["Department of Computer Science, University of Malta, Msida, Malta"],"raw_orcid":"https://orcid.org/0000-0002-6483-9054","affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Malta, Msida, Malta","institution_ids":["https://openalex.org/I197854408"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5083832418","display_name":"Christian Colombo","orcid":"https://orcid.org/0000-0002-2844-5728"},"institutions":[{"id":"https://openalex.org/I197854408","display_name":"University of Malta","ror":"https://ror.org/03a62bv60","country_code":"MT","type":"education","lineage":["https://openalex.org/I197854408"]}],"countries":["MT"],"is_corresponding":false,"raw_author_name":"Christian Colombo","raw_affiliation_strings":["Department of Computer Science, University of Malta, Msida, Malta"],"raw_orcid":"https://orcid.org/0000-0002-2844-5728","affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Malta, Msida, Malta","institution_ids":["https://openalex.org/I197854408"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5059422128","display_name":"Julio Hern\u00e1ndez-Castro","orcid":"https://orcid.org/0000-0002-6432-5328"},"institutions":[{"id":"https://openalex.org/I20581793","display_name":"University of Kent","ror":"https://ror.org/00xkeyj56","country_code":"GB","type":"education","lineage":["https://openalex.org/I20581793"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Julio Hernandez-Castro","raw_affiliation_strings":["School of Computing, Cornwallis South, University of Kent, Canterbury, UK"],"raw_orcid":"https://orcid.org/0000-0002-6432-5328","affiliations":[{"raw_affiliation_string":"School of Computing, Cornwallis South, University of Kent, Canterbury, UK","institution_ids":["https://openalex.org/I20581793"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":{"value":5000,"currency":"EUR","value_usd":5392},"fwci":2.9596,"has_fulltext":true,"cited_by_count":11,"citation_normalized_percentile":{"value":0.93702387,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"22","last_page":"38"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9958000183105469,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9930999875068665,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8646749258041382},{"id":"https://openalex.org/keywords/android","display_name":"Android (operating system)","score":0.838278591632843},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8019882440567017},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.7380701303482056},{"id":"https://openalex.org/keywords/trojan","display_name":"Trojan","score":0.5446187853813171},{"id":"https://openalex.org/keywords/android-malware","display_name":"Android malware","score":0.527276337146759},{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.46010032296180725},{"id":"https://openalex.org/keywords/android-app","display_name":"Android app","score":0.4244408905506134},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.42426034808158875},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.2790183424949646},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.0961574912071228},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.09071660041809082}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8646749258041382},{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.838278591632843},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8019882440567017},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.7380701303482056},{"id":"https://openalex.org/C174333608","wikidata":"https://www.wikidata.org/wiki/Q19635","display_name":"Trojan","level":2,"score":0.5446187853813171},{"id":"https://openalex.org/C2989133298","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android malware","level":3,"score":0.527276337146759},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.46010032296180725},{"id":"https://openalex.org/C2988045736","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android app","level":3,"score":0.4244408905506134},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.42426034808158875},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.2790183424949646},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.0961574912071228},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.09071660041809082}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1007/978-3-030-59817-4_2","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-030-59817-4_2","pdf_url":"https://link.springer.com/content/pdf/10.1007%2F978-3-030-59817-4_2.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},{"id":"pmh:oai:www.um.edu.mt:123456789/91080","is_oa":true,"landing_page_url":"https://www.um.edu.mt/library/oar/handle/123456789/91080","pdf_url":null,"source":{"id":"https://openalex.org/S4306400782","display_name":"OAR@UM (University of Malta)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I197854408","host_organization_name":"University of Malta","host_organization_lineage":["https://openalex.org/I197854408"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"info:eu-repo/semantics/bookPart"},{"id":"pmh:oai:pubmedcentral.nih.gov:7491630","is_oa":true,"landing_page_url":"https://www.ncbi.nlm.nih.gov/pmc/articles/7491630","pdf_url":null,"source":{"id":"https://openalex.org/S2764455111","display_name":"PubMed Central","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Security and Trust Management","raw_type":"Text"}],"best_oa_location":{"id":"doi:10.1007/978-3-030-59817-4_2","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-030-59817-4_2","pdf_url":"https://link.springer.com/content/pdf/10.1007%2F978-3-030-59817-4_2.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"sustainable_development_goals":[{"score":0.5799999833106995,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G1923342024","display_name":null,"funder_award_id":"H2020-SU-SEC-2018","funder_id":"https://openalex.org/F4320332999","funder_display_name":"Horizon 2020 Framework Programme"},{"id":"https://openalex.org/G2187605037","display_name":null,"funder_award_id":"832735","funder_id":"https://openalex.org/F4320332999","funder_display_name":"Horizon 2020 Framework Programme"},{"id":"https://openalex.org/G3520374423","display_name":null,"funder_award_id":"SU-SEC-2018-832735","funder_id":"https://openalex.org/F4320332999","funder_display_name":"Horizon 2020 Framework Programme"}],"funders":[{"id":"https://openalex.org/F4320332999","display_name":"Horizon 2020 Framework Programme","ror":"https://ror.org/00k4n6c32"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3090890096.pdf","grobid_xml":"https://content.openalex.org/works/W3090890096.grobid-xml"},"referenced_works_count":18,"referenced_works":["https://openalex.org/W2015933956","https://openalex.org/W2060537671","https://openalex.org/W2114381667","https://openalex.org/W2125011234","https://openalex.org/W2148519244","https://openalex.org/W2158874007","https://openalex.org/W2700054830","https://openalex.org/W2763184978","https://openalex.org/W2766662084","https://openalex.org/W2770125776","https://openalex.org/W2893610239","https://openalex.org/W2908109201","https://openalex.org/W2910063638","https://openalex.org/W2936514235","https://openalex.org/W2938454325","https://openalex.org/W2942621985","https://openalex.org/W2971630511","https://openalex.org/W3008101892"],"related_works":["https://openalex.org/W2929621094","https://openalex.org/W1996006176","https://openalex.org/W4285325964","https://openalex.org/W2782775281","https://openalex.org/W2560361988","https://openalex.org/W2507113366","https://openalex.org/W3200508744","https://openalex.org/W3025122950","https://openalex.org/W2895504842","https://openalex.org/W2311926078"],"abstract_inverted_index":{"Abstract":[0],"Android":[1,65],"accessibility":[2,66,144,182],"features":[3],"include":[4],"a":[5,100,137,153],"robust":[6],"set":[7,23],"of":[8,24,64,76,152,188],"tools":[9,25],"allowing":[10],"developers":[11],"to":[12,41,56,177,185],"create":[13],"apps":[14],"for":[15,103,132],"assisting":[16],"people":[17],"with":[18,38],"disabilities.":[19],"Unfortunately,":[20],"this":[21,50],"useful":[22],"can":[26,68,112,146],"also":[27],"be":[28,113],"abused":[29],"and":[30,43,83,125,127],"turned":[31],"into":[32],"an":[33],"attack":[34],"vector,":[35],"providing":[36],"malware":[37,77,111,194],"the":[39,54,58,61,73,93,118,133,143,148,167,186],"ability":[40],"interact":[42],"read":[44],"content":[45],"from":[46],"third-party":[47],"apps.":[48],"In":[49,117,161],"work,":[51],"we":[52,121,135,164],"are":[53],"first":[55],"study":[57],"impact":[59],"that":[60,89],"stealthy":[62],"exploitation":[63],"services":[67],"have":[69],"on":[70],"significantly":[71,171],"reducing":[72],"forensic":[74,85,173],"footprint":[75],"attacks,":[78],"thus":[79],"hindering":[80],"both":[81,162],"live":[82],"post-incident":[84],"investigations.":[86],"We":[87],"show":[88,136],"through":[90],"Living":[91],"off":[92],"Land":[94],"(LotL)":[95],"tactics,":[96],"or":[97],"by":[98],"offering":[99],"malware-only":[101],"substitute":[102],"attacks":[104,168,179],"typically":[105],"requiring":[106,193],"more":[107],"elaborate":[108],"schemes,":[109],"accessibility-based":[110],"rendered":[114],"virtually":[115],"undetectable.":[116],"LotL":[119],"approach,":[120],"demonstrate":[122,165],"accessibility-enabled":[123],"SMS":[124],"command":[126],"control":[128],"(C2)":[129],"capabilities.":[130],"As":[131],"latter,":[134],"complete":[138],"cryptocurrency":[139],"wallet":[140],"theft,":[141],"whereby":[142],"trojan":[145],"hijack":[147],"entire":[149],"withdrawal":[150],"process":[151],"widely":[154],"used":[155],"app,":[156],"including":[157],"two-factor":[158],"authentication":[159],"(2FA).":[160],"cases,":[163],"how":[166],"result":[169],"in":[170],"diminished":[172],"evidence":[174],"when":[175],"compared":[176],"similar":[178],"not":[180],"employing":[181],"tools,":[183],"even":[184],"extent":[187],"maintaining":[189],"device":[190],"take-over":[191],"without":[192],"persistence.":[195]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":4},{"year":2021,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
